crw-parse
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues detected. The skill provides instructions and examples for using the 'crw' command-line tool and associated REST API to extract text from PDF files. All identified external resources and tools are owned by the vendor 'us'.
- [DATA_EXFILTRATION]: The skill documents the use of 'curl' to upload files to a remote API. This is the intended behavior for the tool's cloud-based parsing functionality and targets the vendor's legitimate infrastructure.
- [INDIRECT_PROMPT_INJECTION]: As a tool that processes external PDF content, there is an inherent surface for indirect prompt injection if the parsed output is subsequently processed by an LLM without sanitization. However, the skill itself does not contain malicious instructions or bypasses, and this risk is typical for document parsing utilities.
Audit Metadata